447 lines
16 KiB
Python
447 lines
16 KiB
Python
"""Integration: saved-chat CRUD (phase 50, task 02) — the ``/api/chats``
|
|
contract.
|
|
|
|
Real Postgres (``podman compose up -d db``). The router sits behind the
|
|
phase-16 ``require_admin`` gate exactly like ``/api/steering`` (the
|
|
house pattern of ``test_steering_api.py``): anonymous callers get 403 on
|
|
every route; the admin CRUD exercises the auto-title convention (first
|
|
user message, whitespace-collapsed, 120-char cap + the no-user-message
|
|
fallback), the list order (``updated_at desc, id desc``), the
|
|
full-payload round-trip (a ``bor.chat.v1``-shaped brain record carrying
|
|
``sources``/``thinking``/``tools``/``stopped`` survives losslessly),
|
|
the PUT upsert semantics (replacement + title-keep + title-set +
|
|
``updated_at`` bump), and the delete 404/204.
|
|
|
|
Requires: podman compose up -d db
|
|
"""
|
|
from __future__ import annotations
|
|
|
|
import time
|
|
import uuid
|
|
from collections.abc import Iterator
|
|
from datetime import UTC, datetime, timedelta
|
|
from typing import Any
|
|
|
|
import pytest
|
|
from fastapi.testclient import TestClient
|
|
from sqlalchemy import select, text
|
|
from sqlalchemy.orm import Session
|
|
|
|
from app.main import app as fastapi_app
|
|
from app.models import SavedChat
|
|
|
|
FIRST_QUESTION = "How did I install gitlab?"
|
|
EXPLICIT_TITLE = "My backup notes"
|
|
|
|
#: A full ``bor.chat.v1`` brain record (phase 14 shape) — every optional
|
|
#: key present; the round-trip test asserts it survives byte-identical.
|
|
FULL_BRAIN: dict[str, Any] = {
|
|
"who": "brain",
|
|
"text": "Your k3s cluster runs on three nodes — you've got this.",
|
|
"sources": [
|
|
{"source": "Homelab", "path": "kubernetes.md", "title": "Kubernetes Cluster"}
|
|
],
|
|
"deflected": False,
|
|
"suggestions": ["What ports does Traefik expose?"],
|
|
"thinking": "The kubernetes doc covers the cluster layout…",
|
|
"tools": [
|
|
{"name": "read_document", "argument": "Homelab/kubernetes.md"},
|
|
{"name": "list_documents", "argument": None},
|
|
],
|
|
"stopped": False,
|
|
}
|
|
|
|
OUT_KEYS = {"id", "title", "created_at", "updated_at", "message_count", "messages"}
|
|
ROW_KEYS = {"id", "title", "updated_at", "message_count"}
|
|
|
|
|
|
@pytest.fixture(autouse=True)
|
|
def clean_chats(db: Session) -> Iterator[None]:
|
|
"""``saved_chats`` is global state: reset around every test."""
|
|
db.execute(text("TRUNCATE saved_chats"))
|
|
db.commit()
|
|
yield
|
|
db.execute(text("TRUNCATE saved_chats"))
|
|
db.commit()
|
|
|
|
|
|
def _user(text: str) -> dict[str, Any]:
|
|
return {"who": "user", "text": text}
|
|
|
|
|
|
def _simple_conversation() -> list[dict[str, Any]]:
|
|
return [_user(FIRST_QUESTION), {"who": "brain", "text": "You've got this!"}]
|
|
|
|
|
|
def _expect(records: list[dict[str, Any]]) -> list[dict[str, Any]]:
|
|
"""The stored shape of a record list (see app/api/chats.py):
|
|
every record carries all ``bor.chat.v1`` keys, explicit nulls where
|
|
an optional key does not apply (the restore path is null-safe).
|
|
A record that already carries every key (``FULL_BRAIN``) is
|
|
unchanged by this."""
|
|
return [
|
|
{
|
|
"who": m["who"],
|
|
"text": m["text"],
|
|
"sources": m.get("sources"),
|
|
"deflected": m.get("deflected"),
|
|
"suggestions": m.get("suggestions"),
|
|
"thinking": m.get("thinking"),
|
|
"tools": m.get("tools"),
|
|
"stopped": m.get("stopped"),
|
|
}
|
|
for m in records
|
|
]
|
|
|
|
|
|
def _assert_no_chats(admin_client: TestClient) -> None:
|
|
assert admin_client.get("/api/chats").json() == {"chats": []}
|
|
|
|
|
|
# ---------- anonymous: 403 on every route (phase 16 gate) ----------
|
|
|
|
|
|
def test_anonymous_every_route_returns_403(client: TestClient) -> None:
|
|
anon = TestClient(fastapi_app) # fresh jar: truly anonymous
|
|
unknown = uuid.uuid4()
|
|
cases = [
|
|
("GET", "/api/chats", None),
|
|
("POST", "/api/chats", {"messages": _simple_conversation()}),
|
|
("GET", f"/api/chats/{unknown}", None),
|
|
("PUT", f"/api/chats/{unknown}", {"messages": _simple_conversation()}),
|
|
("DELETE", f"/api/chats/{unknown}", None),
|
|
]
|
|
for method, path, body in cases:
|
|
r = anon.request(method, path, json=body)
|
|
assert r.status_code == 403, f"{method} {path} must be 403 for anonymous"
|
|
assert r.json() == {"detail": "admin only"}
|
|
|
|
|
|
# ---------- create ----------
|
|
|
|
|
|
def test_create_returns_201_and_auto_titles(
|
|
admin_client: TestClient, db: Session
|
|
) -> None:
|
|
r = admin_client.post("/api/chats", json={"messages": _simple_conversation()})
|
|
|
|
assert r.status_code == 201
|
|
body = r.json()
|
|
assert set(body) == OUT_KEYS
|
|
assert body["title"] == FIRST_QUESTION # auto-title = first user message
|
|
assert body["message_count"] == 2
|
|
assert body["messages"] == _expect(_simple_conversation())
|
|
uuid.UUID(body["id"]) # valid UUID
|
|
# Fresh row: nothing has updated it, so both stamps agree.
|
|
assert body["created_at"] and body["updated_at"]
|
|
assert abs(
|
|
datetime.fromisoformat(body["created_at"])
|
|
- datetime.fromisoformat(body["updated_at"])
|
|
).total_seconds() < 5
|
|
rows = db.scalars(select(SavedChat)).all()
|
|
assert [row.title for row in rows] == [FIRST_QUESTION]
|
|
|
|
|
|
def test_create_auto_title_collapses_whitespace_and_truncates_to_120(
|
|
admin_client: TestClient,
|
|
) -> None:
|
|
long_text = "How did I install " + "x" * 200
|
|
r = admin_client.post(
|
|
"/api/chats", json={"messages": [_user(long_text), {"who": "brain", "text": "ok"}]}
|
|
)
|
|
assert r.status_code == 201
|
|
assert len(r.json()["title"]) == 120
|
|
assert r.json()["title"] == long_text[:120]
|
|
|
|
# Multi-space / tab / newline runs collapse to single spaces.
|
|
r = admin_client.post(
|
|
"/api/chats", json={"messages": [_user("What is\nmy\tTraefik port?")]}
|
|
)
|
|
assert r.status_code == 201
|
|
assert r.json()["title"] == "What is my Traefik port?"
|
|
|
|
|
|
def test_create_honors_explicit_title(admin_client: TestClient) -> None:
|
|
r = admin_client.post(
|
|
"/api/chats",
|
|
json={"title": f" {EXPLICIT_TITLE} ", "messages": _simple_conversation()},
|
|
)
|
|
assert r.status_code == 201
|
|
assert r.json()["title"] == EXPLICIT_TITLE # trimmed, not auto-titled
|
|
|
|
|
|
def test_create_blank_title_falls_back_to_auto_title(admin_client: TestClient) -> None:
|
|
r = admin_client.post(
|
|
"/api/chats", json={"title": " \t\n ", "messages": _simple_conversation()}
|
|
)
|
|
assert r.status_code == 201
|
|
assert r.json()["title"] == FIRST_QUESTION
|
|
|
|
|
|
def test_create_without_user_message_falls_back_to_chat_id(admin_client: TestClient) -> None:
|
|
# Defensive — the UI cannot produce a conversation with no user
|
|
# message; the auto-title then names the row after its own id.
|
|
r = admin_client.post(
|
|
"/api/chats", json={"messages": [{"who": "brain", "text": "hello"}]}
|
|
)
|
|
assert r.status_code == 201
|
|
body = r.json()
|
|
assert body["title"] == f"Chat {body['id'][:8]}"
|
|
|
|
|
|
def test_create_round_trips_full_brain_record(admin_client: TestClient) -> None:
|
|
r = admin_client.post(
|
|
"/api/chats", json={"messages": [_user(FIRST_QUESTION), FULL_BRAIN]}
|
|
)
|
|
assert r.status_code == 201
|
|
# The bor.chat.v1-shaped payload round-trips losslessly: every
|
|
# optional key (sources/deflected/suggestions/thinking/tools/
|
|
# stopped) survives identical.
|
|
assert r.json()["messages"][1] == FULL_BRAIN
|
|
|
|
|
|
def test_create_rejects_empty_messages(admin_client: TestClient) -> None:
|
|
assert admin_client.post("/api/chats", json={"messages": []}).status_code == 422
|
|
_assert_no_chats(admin_client)
|
|
|
|
|
|
def test_create_rejects_unknown_who(admin_client: TestClient) -> None:
|
|
r = admin_client.post(
|
|
"/api/chats", json={"messages": [{"who": "alien", "text": "hi"}]}
|
|
)
|
|
assert r.status_code == 422
|
|
_assert_no_chats(admin_client)
|
|
|
|
|
|
def test_create_rejects_empty_text(admin_client: TestClient) -> None:
|
|
assert (
|
|
admin_client.post("/api/chats", json={"messages": [_user("")]})
|
|
).status_code == 422
|
|
_assert_no_chats(admin_client)
|
|
|
|
|
|
def test_create_rejects_extra_message_keys(admin_client: TestClient) -> None:
|
|
# A corrupted / HTML-shaped payload must not cross the boundary.
|
|
message = _user(FIRST_QUESTION)
|
|
message["html"] = "<b>not allowed</b>"
|
|
assert admin_client.post("/api/chats", json={"messages": [message]}).status_code == 422
|
|
_assert_no_chats(admin_client)
|
|
|
|
|
|
def test_create_rejects_title_over_500(admin_client: TestClient) -> None:
|
|
assert (
|
|
admin_client.post(
|
|
"/api/chats", json={"title": "t" * 501, "messages": _simple_conversation()}
|
|
)
|
|
).status_code == 422
|
|
|
|
|
|
# ---------- list ----------
|
|
|
|
|
|
def test_list_empty(admin_client: TestClient) -> None:
|
|
r = admin_client.get("/api/chats")
|
|
assert r.status_code == 200
|
|
assert r.json() == {"chats": []}
|
|
|
|
|
|
def test_list_orders_by_updated_at_desc(admin_client: TestClient, db: Session) -> None:
|
|
base = datetime.now(UTC)
|
|
db.add_all(
|
|
[
|
|
SavedChat(
|
|
title="oldest",
|
|
messages=[_user("one")],
|
|
updated_at=base,
|
|
),
|
|
SavedChat(
|
|
title="newest",
|
|
messages=[_user("two"), _user("three")],
|
|
updated_at=base + timedelta(hours=2),
|
|
),
|
|
SavedChat(
|
|
title="middle",
|
|
messages=[_user("four")],
|
|
updated_at=base + timedelta(hours=1),
|
|
),
|
|
]
|
|
)
|
|
db.commit()
|
|
|
|
r = admin_client.get("/api/chats")
|
|
assert r.status_code == 200
|
|
body = r.json()
|
|
assert [c["title"] for c in body["chats"]] == ["newest", "middle", "oldest"]
|
|
for c in body["chats"]:
|
|
assert set(c) == ROW_KEYS
|
|
uuid.UUID(c["id"])
|
|
assert "messages" not in c # no payloads in the list
|
|
|
|
|
|
def test_list_reports_message_count(admin_client: TestClient) -> None:
|
|
admin_client.post("/api/chats", json={"messages": _simple_conversation()})
|
|
body = admin_client.get("/api/chats").json()
|
|
assert [c["message_count"] for c in body["chats"]] == [2]
|
|
|
|
|
|
# ---------- get ----------
|
|
|
|
|
|
def test_get_returns_full_payload_round_trip(admin_client: TestClient) -> None:
|
|
created = admin_client.post(
|
|
"/api/chats",
|
|
json={"title": EXPLICIT_TITLE, "messages": [_user(FIRST_QUESTION), FULL_BRAIN]},
|
|
).json()
|
|
|
|
r = admin_client.get(f"/api/chats/{created['id']}")
|
|
assert r.status_code == 200
|
|
body = r.json()
|
|
assert set(body) == OUT_KEYS
|
|
assert body["id"] == created["id"]
|
|
assert body["title"] == EXPLICIT_TITLE
|
|
assert body["message_count"] == 2
|
|
# Byte-identical payload: the brain record with sources/thinking/
|
|
# tools/stopped (incl. the `argument: null` tool) survives the trip
|
|
# to Postgres and back.
|
|
assert body["messages"] == _expect([_user(FIRST_QUESTION), FULL_BRAIN])
|
|
|
|
|
|
def test_get_unknown_chat_returns_404(admin_client: TestClient) -> None:
|
|
r = admin_client.get(f"/api/chats/{uuid.uuid4()}")
|
|
assert r.status_code == 404
|
|
assert r.json() == {"detail": "unknown chat"}
|
|
|
|
|
|
def test_get_invalid_id_returns_422(admin_client: TestClient) -> None:
|
|
assert admin_client.get("/api/chats/not-a-uuid").status_code == 422
|
|
|
|
|
|
# ---------- update (PUT) — the re-Save upsert ----------
|
|
|
|
|
|
def test_put_replaces_messages_and_bumps_updated_at(admin_client: TestClient) -> None:
|
|
created = admin_client.post(
|
|
"/api/chats",
|
|
json={"title": EXPLICIT_TITLE, "messages": _simple_conversation()},
|
|
).json()
|
|
# A second, newer chat — it currently lists first.
|
|
other = admin_client.post(
|
|
"/api/chats", json={"messages": [_user("second question")], "title": "Other"}
|
|
).json()
|
|
assert admin_client.get("/api/chats").json()["chats"][0]["id"] == other["id"]
|
|
updated_before = created["updated_at"]
|
|
|
|
time.sleep(0.1) # now() has µs resolution — make the bump observable
|
|
new_messages = [
|
|
_user("How do I prune deleted docs?"),
|
|
{"who": "brain", "text": "Use --prune."},
|
|
]
|
|
r = admin_client.put(f"/api/chats/{created['id']}", json={"messages": new_messages})
|
|
|
|
assert r.status_code == 200
|
|
body = r.json()
|
|
assert body["id"] == created["id"]
|
|
assert body["title"] == EXPLICIT_TITLE # absent title keeps the current one
|
|
assert body["message_count"] == 2
|
|
assert body["messages"] == _expect(new_messages) # full replacement
|
|
assert datetime.fromisoformat(body["created_at"]) == datetime.fromisoformat(
|
|
created["created_at"]
|
|
) # editing does not redate creation
|
|
assert datetime.fromisoformat(body["updated_at"]) > datetime.fromisoformat(
|
|
updated_before
|
|
), "updated_at must bump on a re-Save (onupdate=func.now())"
|
|
# The list order follows the bump: this row is first again.
|
|
body_list = admin_client.get("/api/chats").json()["chats"]
|
|
assert body_list[0]["id"] == created["id"]
|
|
|
|
|
|
def test_put_sets_title_when_supplied(admin_client: TestClient) -> None:
|
|
created = admin_client.post(
|
|
"/api/chats", json={"messages": _simple_conversation()}
|
|
).json()
|
|
|
|
r = admin_client.put(
|
|
f"/api/chats/{created['id']}",
|
|
json={"title": "Renamed notes", "messages": _simple_conversation()},
|
|
)
|
|
|
|
assert r.status_code == 200
|
|
assert r.json()["title"] == "Renamed notes"
|
|
assert (
|
|
admin_client.get(f"/api/chats/{created['id']}").json()["title"] == "Renamed notes"
|
|
)
|
|
|
|
|
|
def test_put_blank_title_keeps_current(admin_client: TestClient) -> None:
|
|
created = admin_client.post(
|
|
"/api/chats",
|
|
json={"title": EXPLICIT_TITLE, "messages": _simple_conversation()},
|
|
).json()
|
|
|
|
r = admin_client.put(
|
|
f"/api/chats/{created['id']}", json={"title": " ", "messages": _simple_conversation()}
|
|
)
|
|
|
|
assert r.status_code == 200
|
|
assert r.json()["title"] == EXPLICIT_TITLE
|
|
|
|
|
|
def test_put_unknown_chat_returns_404(admin_client: TestClient) -> None:
|
|
r = admin_client.put(
|
|
f"/api/chats/{uuid.uuid4()}", json={"messages": _simple_conversation()}
|
|
)
|
|
assert r.status_code == 404
|
|
assert r.json() == {"detail": "unknown chat"}
|
|
|
|
|
|
def test_put_rejects_empty_messages(admin_client: TestClient) -> None:
|
|
created = admin_client.post(
|
|
"/api/chats", json={"messages": _simple_conversation()}
|
|
).json()
|
|
assert (
|
|
admin_client.put(f"/api/chats/{created['id']}", json={"messages": []})
|
|
).status_code == 422
|
|
# The original payload is untouched.
|
|
assert (
|
|
admin_client.get(f"/api/chats/{created['id']}").json()["messages"]
|
|
== _expect(_simple_conversation())
|
|
)
|
|
|
|
|
|
def test_put_rejects_extra_message_keys(admin_client: TestClient) -> None:
|
|
created = admin_client.post(
|
|
"/api/chats", json={"messages": _simple_conversation()}
|
|
).json()
|
|
bad = _user("hi")
|
|
bad["innerHTML"] = "<script>alert(1)</script>"
|
|
r = admin_client.put(
|
|
f"/api/chats/{created['id']}", json={"messages": [bad, FULL_BRAIN]}
|
|
)
|
|
assert r.status_code == 422
|
|
assert (
|
|
admin_client.get(f"/api/chats/{created['id']}").json()["messages"]
|
|
== _expect(_simple_conversation())
|
|
)
|
|
|
|
|
|
# ---------- delete ----------
|
|
|
|
|
|
def test_delete_returns_204_and_removes(admin_client: TestClient, db: Session) -> None:
|
|
created = admin_client.post("/api/chats", json={"messages": _simple_conversation()}).json()
|
|
|
|
assert admin_client.delete(f"/api/chats/{created['id']}").status_code == 204
|
|
assert admin_client.get(f"/api/chats/{created['id']}").status_code == 404
|
|
assert admin_client.get("/api/chats").json() == {"chats": []}
|
|
assert db.scalars(select(SavedChat)).all() == []
|
|
|
|
|
|
def test_delete_unknown_chat_returns_404(admin_client: TestClient) -> None:
|
|
r = admin_client.delete(f"/api/chats/{uuid.uuid4()}")
|
|
assert r.status_code == 404
|
|
assert r.json() == {"detail": "unknown chat"}
|
|
|
|
|
|
def test_delete_invalid_id_returns_422(admin_client: TestClient) -> None:
|
|
assert admin_client.delete("/api/chats/not-a-uuid").status_code == 422
|